TimoBy Amotion AI

Governance, Risk and Responsible Use: CCAO-F domain 6 study guide

CCAO-F · Governance, Risk, and Responsible Use (15% of the exam)

Governance, Risk and Responsible Use is domain 6 of the Claude Certified Associate Foundations exam, 15% of the scored items. It tests whether you can tell a good use of Claude from a risky one, protect sensitive data before it reaches Claude, follow your organisation's AI policy, and keep people accountable for decisions that affect others.

What the official guide covers

The Claude Certified Associate Foundations exam guide (version 1.0, effective July 2026) lists four tasks under domain 6, Governance, Risk, and Responsible Use:

What the guide listsWhat it means in practice
Identify appropriate and inappropriate use casesKnow which tasks suit Claude, which need expert sign-off and which Claude should not do
Apply data sensitivity, regulatory and privacy considerationsClassify data before using it; remove or mask what policy restricts
Follow organisational AI policies and governance standardsUse approved accounts, tools and connectors; record and escalate as the policy says
Understand the ethical implications of AI usageConsider bias, fairness, transparency and who is affected by the output

Appropriate, needs sign-off, or not for Claude

UseCategoryWhat makes it so
Drafting internal emails, summarising your own meeting notesAppropriate with your own reviewLow stakes, you know the source
Research summaries, first drafts of reportsAppropriate with fact-checkingErrors can be caught against sources
Customer-facing content, public statementsNeeds owner sign-offErrors reach people who act on them
Legal, financial, medical or regulatory contentNeeds a qualified specialist's reviewClaude does not replace professional judgement
Deciding who is hired, promoted, disciplined or refused a serviceA person decides; Claude may only organise evidenceDecisions about people need human accountability
Content that deceives people or breaks law or company policyNot appropriateNo review makes it acceptable

Screening a new use case

Run four questions on any proposed use:

  • Reversibility. If an output is wrong, can someone catch and reverse it before harm is done?
  • Cost of error. What happens if it is wrong, and to whom?
  • Human element. Does the task need empathy, relationship or creative judgement that should come from a person?
  • Accountability. Who answers for the outcome, and can they really own an AI-produced result?

The questions interact, so name the one that decides the case: the criterion that, if it changed, would move the use into a different category. A client condolence note carries low risk and can be undone, yet the relationship means a person should write it. A financial summary is high stakes, yet acceptable once a named reviewer signs it off before use.

"Appropriate with review" needs a defined gate

This is the category most often got wrong. "A human stays in the loop" is not a gate. A gate names who reviews (the role that is accountable, not whoever is free), what they check (accuracy against the account record, fairness, policy), and when (before the output is used). Example: drafted replies to billing complaints are appropriate with review if a support agent checks each one against the customer's actual account, and adjusts the tone, before it is sent. A gate you cannot express in that form means the use is not ready.

Classify data before you use it

Decide what kind of data you hold before you paste, upload or connect it.

Data classExamplesWhat to do
PublicPublished reports, press releasesUse freely
InternalTeam plans, process notesUse in the company's approved Claude workspace
ConfidentialContracts, pricing, unreleased plansUse only where policy allows, in the approved workspace
Personal or regulatedCustomer names and contact details, employee records, health or financial detailsRemove, mask or aggregate first unless policy explicitly permits use

Techniques that let the work go ahead safely:

  • Minimise. Share only the columns or passages the task needs.
  • Mask. Replace names and identifiers with labels such as Customer A.
  • Aggregate. Give totals by region instead of rows per customer.
  • Use the approved place. A personal account is not the same as the company workspace, even for the same person.

If the data could fall in either of two classes, handle it as the more sensitive class until you confirm. Redaction has two failure modes. Partial redaction: strip the name but keep an account number, an unusual job title or an exact date, and a person in a small group can still be identified. Redaction that breaks the task: when the task really depends on the identifiers, masking is not the answer; confirm an approved route for that data or leave it out.

What the Claude apps do and do not control

  • Work accounts belong to the organisation. On Team and Enterprise plans, the organisation's Primary Owner manages the account and its data, and can limit which features members use.
  • Enterprise retention is set by owners. Owners on Enterprise plans can set how long conversation and project data is kept.
  • Incognito is not a policy exception. Incognito chats are not saved to your chat history or to memory, but Anthropic still retains them for a period, and on Team and Enterprise plans they are included in the data exports available to owners. They are only available outside Projects. Incognito controls what is remembered; it does not answer whether the data was allowed there in the first place. For regulated data, settle that question first.
  • Memory can be turned off for everyone on Enterprise. Enterprise owners can disable memory for the organisation; Team plan members manage their own memory settings.
  • Connectors mirror permissions. Claude sees only what your account can already see in Google Workspace, and Gmail send, reply and forward actions ask for your approval by default. On Team and Enterprise plans, an Owner must enable these connectors before members can use them.

Treat a Skill like software you are about to install

A Skill is a folder of instructions and often scripts that Claude runs. Anthropic's help centre names prompt injection and data exfiltration as the main risks, and advises installing Skills only from trusted sources and auditing a less-trusted Skill's files first. Three checks:

CheckQuestion
SourceWho published it? Anthropic Skills and ones your organisation provisioned are the safer start
ReachWhat could it touch in the chats where it will run, and is that in proportion to the job? A formatting Skill whose instructions go far beyond formatting is a warning sign
FitIs it the right tool, or more capability than the task needs?

The outcome is enable (all three clear), escalate to your admin or security team (useful, but the source is unclear or the reach looks broad), or decline (clearly out of proportion). A Skill from another team, or one a colleague found and recommends, is not vetted until someone checks what it touches. Switch on only the connectors a task needs.

Pre-use checklist

BEFORE USING CLAUDE ON THIS TASK
[ ] Is this use allowed by our AI policy? (If unsure, ask the policy owner.)
[ ] Am I in the approved company workspace, not a personal account?
[ ] What is the most sensitive data involved? Public / internal /
    confidential / personal or regulated
[ ] Have I removed, masked or aggregated anything policy restricts?
[ ] Are the connectors I have switched on approved and needed?
[ ] Who could be affected by the output, and could it treat any group
    unfairly?
[ ] Who reviews the output, and who owns the final decision?
[ ] Does our policy require me to say that AI helped produce this?

The ethical questions to ask

QuestionWhy it mattersWhat to do
Could the output be biased?Claude can reflect one-sided sources or framingCheck who is missing; review who an automated screen drops, not only who it keeps
Who is accountable?Claude cannot take responsibilityName the person who approves and owns the result
Are people told AI was used?Readers may rely on it differentlyFollow your organisation's disclosure rules
Is anyone relying on it too much?Over-reliance lets errors throughKeep review steps even when results look good
Does it affect a person's rights or livelihood?The cost of an error is highKeep a person as the decision maker

For a case no rule settles, note the people affected, the possible harms, what fairness would look like, and the disclosure the setting needs. When unsure about disclosure, disclose. If many people are affected or the harm could be serious, take your written reasoning to your AI governance or ethics function rather than deciding alone.

Policy also drifts in practice. Periodically compare what your team does with the policy: an unapproved upload, a Skill enabled without a check, a review gate skipped under deadline pressure.

When to escalate

Escalate to your AI policy owner, privacy or legal team when you are unsure whether data or a use is allowed, and to Claude Architects or Developers when a task needs custom integrations, automation at scale or technical controls.

Rules that decide exam answers

  • Fix the data, then do the task. When personal data is restricted, the best answer removes or masks it and carries on; uploading as-is and abandoning the work are both wrong.
  • Telling Claude to forget is not a control. Instructions to Claude, incognito chats and good intentions do not replace the data rules in your policy.
  • Use the approved workspace. Company data belongs in the company's Claude account, not a personal one.
  • People decide about people. Claude can organise evidence for a hiring or performance decision; it does not make the decision.
  • Fix the friction behind a workaround. If staff use personal accounts because the approved workspace is slower, the organisation owns that gap: make the approved route the easy one.
  • When the policy is unclear, ask. Escalating to the policy owner beats both guessing and refusing to use Claude at all.

Where it appears in the exam

Domain 6 carries 15% of the exam, around 9 of the 60 items. Questions describe a task with a risk in it, such as personal data, a decision about people, a request outside policy or content that could be unfair, and ask for the most appropriate action.

Two sample questions

These are original Timo practice questions. They are not official exam questions.

Question 1

An HR partner wants Claude to rank 40 internal applicants for promotion from their review comments and send the top five to the panel as the final shortlist. The company uses a Claude Enterprise workspace. What is the most appropriate approach?

Answer: D. Claude can organise evidence within policy, but people must make and own decisions about people. A and B hand the decision to Claude, and masking names in B does not change that. C gives up a useful, controlled task without need.

Question 2

A sales rep wants to paste a confidential client contract into Claude to draft a reply. Policy allows confidential data only in the company's Claude workspace. He is signed in to a personal account and suggests an incognito chat "so nothing is saved". What should he do?

Answer: B. The policy names the approved workspace, and incognito chats, though kept out of history and memory, are still retained by Anthropic for a period. A misreads what incognito does, and C and D still put confidential terms into an account the policy does not allow.

Build exercise

  1. Find your organisation's AI policy. List what it says about approved tools, data classes, disclosure and escalation.
  2. Take a real dataset you would like Claude to analyse. Classify each column, then mask or remove what the policy restricts.
  3. Run the pre-use checklist on three tasks you did with Claude this month. Note any you would now handle differently.
  4. Write a one-paragraph escalation note for a use case where the policy is unclear, addressed to your policy owner.

Practise this topic

Sources